Comment 3 for bug 1648806

Revision history for this message
Martin Pitt (pitti) wrote : Re: Arbitrary code execution through crafted CrashDB in .crash files

Proposed patch (including tests) for the code execution via crafted CrashDB: fields, against current trunk.

I will now look into the other aspect (arbitrary hook execution via crafted Package:/Source: fields). I think this deserves a separate CVE number.